Bug #76671 [Opn->Nab]: bypass strpos verification
| From: | rasmus@php.net | Date: | Fri, 27 Jul 2018 02:00:48 +0000 |
| Subject: | Bug #76671 [Opn->Nab]: bypass strpos verification | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-216484@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=76671&edit=1
ID: 76671
Updated by: rasmus@php.net
Reported by: guilhermeassmannn at gmail dot com
Summary: bypass strpos verification
-Status: Open
+Status: Not a bug
Type: Bug
Package: Strings related
Operating System: MacOS High Sierra & Ubuntu 16.04
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
strpos() is a low-level string manipulation function. If the string you are parsing has a
higher-level meaning, you need to handle that yourself before calling strpos(). That might mean
calling urldecode() if you know the string is an encoded url.
Previous Comments:
------------------------------------------------------------------------
[2018-07-27 01:33:40] guilhermeassmannn at gmail dot com
Description:
------------
The bug is more related to when we send a string with encode to the strpos(), when we sent a string
with double encode we were able to bypass the verification, using %2570hp if the case is like
strpos($string, "php").
Test script:
---------------
$x = $_GET['x']; //?x=file:///var/www/html/readme.%2570hp
$pos = strpos($x,"php");
if($pos){
exit("denied");
}
$ch = curl_init();
curl_setopt($ch,CURLOPT_URL,"$x");
curl_setopt($ch,CURLOPT_RETURNTRANSFER,true);
$result = curl_exec($ch);
echo $result;
Expected result:
----------------
denied
Actual result:
--------------
<?php
//readme
?>
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=76671&edit=1